Comment 3 for bug 2002889

Revision history for this message
Klaus Darilion (klausdarilion) wrote :

Hello!

I hit the same bug. The problem is an incomplete backport for XSA-423.

Here is the same bugreport from debian:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1026035

http://changelogs.ubuntu.com/changelogs/pool/main/l/linux/linux_5.15.0-58.64/changelog mentions
" * CVE-2022-3643
    - xen/netback: Ensure protocol headers don't fall in the non-linear area"

but this is incomplete. Also this commit must be backported:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/drivers/net/xen-netback?h=v5.15.90&id=dec5abd91abc700dcb869f8056bc1f48d045ff97

IMO this is critical, as this regression breaks networking for XEN VMs.